Public proof ledger

Inspect the evidence before buying CapitalGuard.

This page collects the real public surfaces behind the product: package scope, checkout readiness, delivery vault, scanner assets, demos, release notes, and claim boundaries.

3

Public license products

10

AI-agent exposure modules

5

Pro scan credits

1 year

Updates included

Checkout evidence

Three fixed license packages are ready to buy.

Each product page explains scope before payment. Customers continue to hosted checkout from the selected product page.

1 repo scan

Starter License

Planned regular €199Save €50
€149

Protect everyday AI use and your first repository.

5 repo scans

Pro License

Planned regular €699Save €200
€499

Make AI-agent exposure visible, governable, and provable.

25 repo scans

Agency License

Planned regular €2,799Save €800
€1,999

Turn AI-agent security into a client-ready delivery system.

Live

Hosted checkout

Starter, Pro, and Agency route customers to Stripe-hosted payment pages.

Live

Delivery vault

Every license has a post-payment activation, scan intake, customer kit, and access recovery path.

Available

Scanner assets

The customer kit includes a guarded installer, policy template, safe-use guide, and delivery checklist.

Beta

Runtime gate

Enforced Mode removes ambient host authority, Delegation Firewall attenuates child authority, and MCP Integrity Gate pins external tool identity and schemas.

Public

Verification surface

Paid customers can verify restrained badge claims after authorization and operator approval.

Product evidence

Customers can inspect the workflow before checkout.

The demos are not customer results. They are product surfaces that show the report style, delivery path, scanner intake, policy generator, dashboard preview, and verification flow.

Open Demo Library

Contained mode

Enforced Mode Runtime Gate

Inspect the filtered workspace, digest-pinned OCI boundary, authenticated broker, replay protection, and exact limits of the contained session.

Signature

CapitalGuard AccessGraph

Explore the action-to-asset map, required controls, and privacy-safe Guardprint that distinguish CapitalGuard from a generic code scanner.

Playbooks

Prevention Playbooks

Build package-specific action packets for secret exposure, prompt injection, workflow risk, and customer data context.

Guardrails

Guardrail Installer

Inspect the local installer and policy planner for blocked paths, protected files, approval gates, and redaction rules.

Scanner

Repo Exposure Scanner

Run a browser-side triage scan on pasted file trees and redacted config signals before buying or submitting licensed scope.

Service

License Console

Open the service workflow customers use for activation, scan inventory, authorized intake, reports, downloads, and monitoring readiness.

Checklist

AI-Agent Checklist

Use the public checklist to identify missing repository controls and route customers to the right license path.

Report

Sample Risk Report

Inspect the kind of finding evidence a customer receives: severity, affected path, business impact, confidence, and preventive control.

Delivery

Customer Delivery Vault

See the post-checkout flow that gives customers activation, scan intake, access recovery, and customer-kit downloads.

Scanner

Scanner Intake

Review the authorization-first scan intake used before any repository scope is handled.

Policy

Policy Generator

Generate practical policy starters for AI coding tools with repository access.

Dashboard

Dashboard Preview

View the operational dashboard concept for risk score, dangerous files, permissions, and policy status.

Trust

Public Badge Verification

Check the public verification surface for teams that need a restrained proof point after paid review.

Downloadable assets

The customer kit has tangible security deliverables.

Repository Exposure Evidence BriefConcise release summary for the six-case synthetic repository exposure benchmark, with reproducible artifacts and explicit limitations.Repository Exposure BenchmarkSix disclosed synthetic exposure classes, case-level results, fixture pack, release hashes, and stated limits.Agent Runtime Gate BenchmarkTwenty-two reproducible containment and broker cases with a fixture pack, release hashes, and explicit limitations.Enforced ModeFiltered workspace, hardened OCI session, authenticated broker, one-time approval leases, and tamper-evident events.Agent Delegation FirewallPublic target-binding, authority-attenuation, no-fan-out, expiry, depth, replay, and residual-boundary contract.Agent Delegation Boundary BenchmarkTwelve fixed synthetic cases for signed chains, authority attenuation, actor and policy binding, depth, and atomic single use.MCP Integrity GatePublic server-identity, tool-inventory, schema-drift, side-effect approval, replay, output-quarantine, and residual-boundary contract.MCP Tool Integrity BenchmarkPublisher-run synthetic evidence for identity, tool-description, input-schema, approval, replay, quarantine, and size-boundary changes.MCP Tool Review GuideA cited five-step workflow and blank review register for server identity, tool contracts, authority, approvals, and evidence.Local Guardrail InstallerVerified customer download for local repository policy and AI-agent precautions.Safe-Use GuidePractical public guidance with the full operating file reserved for verified customers.Policy FileInteractive policy rules for protected paths, approvals, and redaction.License Kit ArchiveProtected customer deliverables unlocked with an active license and purchase email.

Release ledger

Shipping history is visible instead of vague hype.

Product releases are listed with dates and concrete surfaces so customers can see what exists now.

MCP Integrity Gate 0.1

Signed tool inventories and output quarantine

July 18, 2026

Every approved MCP server is locked to one measured identity digest, protocol version, exact tool list, descriptions, input schemas, and output schemas.
Mutating and unknown tools require an already-verified one-time gateway approval; every request is reserved before invocation so sequential and concurrent replay fail closed.
Untrusted provider output is quarantined outside agent context by default, while public schemas, vectors, release digests, and residual boundaries make the control inspectable.

Agent Delegation Firewall 0.1

Single-use authority chains for multi-agent work

July 18, 2026

Every signed delegation binds one target agent, task, policy, root session, capability subset, expiry, and maximum chain depth.
A parent envelope can be spent on one child or one terminal request, never both; sequential and concurrent replay fail closed in a lock-protected local ledger.
Public schemas, synthetic signatures, threat model, support matrix, and release digests state the exact control and the live-adapter boundary.

Enforced Mode 0.3

Unified runtime trust chain for contained AI-agent sessions

July 19, 2026

The licensed launcher builds a policy-filtered read-only workspace and starts a digest-pinned OCI image without direct network, host-source, Docker-socket, or ambient-secret access.
Every dynamic request is task-bound, signed as model-originated context, derived as untrusted, checked against sequence history, and then evaluated by the default-deny gateway.
Separate Context Provenance and Runtime Sequence authorities, external security-state roots, and authenticated pending state make replay, rollback, and uncertain crash recovery fail closed.
The 22-case publisher-operated benchmark and signed open challenge publish the exact boundary, evidence, provenance, and limitations without unsupported competitor scores.

Agent Action Gateway 0.1

Routed operation enforcement with replay-protected approvals

July 16, 2026

The licensed gateway enforces supported file, command, and metadata-only network operations submitted through its local adapters.
Approval leases are signed, short-lived, bound to exact request and policy digests, and atomically limited to one use.
Every decision appends a privacy-safe tamper-evident event and states that operations bypassing the gateway remain outside its control.

Claim boundaries

Clear boundaries make the product easier to trust.

No repository is scanned until ownership or written authorization is confirmed.
Secrets and sensitive values are redacted in customer-facing reports and demos.
CapitalGuard detects exposure and recommends precautions; it does not guarantee breach prevention.
Policy artifacts return declared decisions; they do not intercept runtime operations or prove enforcement.
Delegation Firewall authorizes a signed handoff but does not start the target process or replace a required approval lease.
MCP Integrity Gate controls routed calls only; direct calls, dishonest identity measurement, approved-tool vulnerabilities, and host compromise remain outside its authority.
Public badge claims are issued only after payment, authorization, scan completion, and operator approval.
Published proof uses product evidence, release notes, and checkout status instead of unsupported testimonials.

Ready to buy

Start with the license that matches your repo scope.